Feature

REST API for in-app purchases: RevenueCat-compatible v1 and v2 for subscription apps

RevenueDot serves REST API v1 and every one of the 128 operations in RevenueCat's REST API v2, with the same paths, list envelope and error format. Server code written for RevenueCat works after you change the base URL and the secret key. Of the 128, 126 do real work and 2 invoice operations answer on purpose.

Free up to $10,000 a month in tracked revenue. Works with the RevenueCat SDK you already ship.

All 128 v2 operations

Projects, apps, products, entitlements, offerings, packages, customers, subscriptions, purchases, charts, discounts and more.

Secret keys with permissions

Keys carry RevenueCat-style permissions such as customer_information:customers:read_write.

One OpenAPI 3.1 document

Every operation names its source file and permissions, and a script checks the document against the server's routes.

Extensions marked

Operations that exist only in RevenueDot carry x-revenuedot-extension: true.

Which APIs does one RevenueDot server answer?

RevenueDot follows RevenueCat's REST API v2 paths, objects, pagination and errors, and adds its own operations for features RevenueCat's API does not have. The reference is generated from the OpenAPI document.

APIPathsAuthOperations
SDK endpoints and store notifications/v1/..., /rcbilling/...Public app key62
REST API v1/v1/subscribers/...Secret key10
REST API v2/v2/projects/...Secret key or dashboard session160 in the reference, covering RevenueCat's 128
RevenueDot extensions/v2/..., /pay/...Secret key, session or none149
Webhooks (sent by RevenueDot)Your URLHMAC signature22 event types

Counts come from the RevenueDot API reference.

Steps

How to call the REST API with a secret key

  1. 01

    Create a secret key

    Open API keys in the dashboard or call POST /v2/projects/{project_id}/api_keys. The key starts with sk_ and is shown once. Give it only the permissions it needs.

  2. 02

    Set the base URL

    Use https://api.revenuedot.app on RevenueDot Cloud, or your own server. Send the key as Authorization: Bearer sk_...

  3. 03

    Call an endpoint

    Lists return an object, items, next_page and url. limit is 1 to 100 with a default of 20. Follow next_page to page.

  4. 04

    Handle errors

    Errors use RevenueCat's v2 body: object, type, message, param, doc_url and retryable. A missing permission answers 403 and names it.

How do you get a customer with REST API v2?

Customers are addressed by any of their app user ids. A public app key on a v2 endpoint answers 403, because v2 needs a secret key.

Get a customercurl
curl -s "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/customers/user_1" \
  -H "Authorization: Bearer $SECRET_KEY"

How do you grant access with the API?

Grant promotional access until expires_at, in epoch milliseconds. A grant ending within 2 hours of an existing grant for the same entitlement changes nothing. REST API v1 has the same action at POST /v1/subscribers/{app_user_id}/entitlements/{entitlement}/promotional.

Grant an entitlementcurl
curl -s -X POST "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/customers/user_1/actions/grant_entitlement" \
  -H "Authorization: Bearer $SECRET_KEY" -H "Content-Type: application/json" \
  -d '{"entitlement_id":"entl1v0bp6r0qs","expires_at":1830000000000}'

What do store actions do through the API?

  • Google Play: cancel, refund and revoke a subscription, defer a renewal, and refund one order or a one-time purchase.
  • App Store: extend a subscription, and extend every active subscriber of a product. Apple does not let a server cancel or refund, so those answer 422 for App Store subscriptions.
  • Restore by order id: find a store purchase by its order id and give it to a customer. It works with Google Play and App Store order ids.
  • Create in store: create a product in App Store Connect, or a Google Play subscription with one listing.
  • The 2 invoice operations exist only for RevenueCat Billing. RevenueDot answers them with responses valid against RevenueCat's spec, so a client never sees an unknown route.

FAQ

REST API: questions people ask

Does RevenueDot have a RevenueCat-compatible REST API?

Yes. RevenueDot serves REST API v1 and all 128 operations of RevenueCat's REST API v2, with the same paths, objects, pagination and error format. Existing scripts keep working when you change the base URL and the secret key.

How do I authenticate to the RevenueDot API?

Send Authorization: Bearer sk_ with a project secret key for REST API v1 and v2. Public app keys, such as appl_ or goog_, are for the SDK endpoints and answer 403 on v2. Secret keys carry permissions, and a key can only create keys with permissions it holds.

Is there an OpenAPI spec for RevenueDot?

Yes. The OpenAPI 3.1 document is served at revenuedot.app/docs/api/openapi.yaml. Import it into Postman, Insomnia or Bruno, or generate a client. Each operation lists its permissions and the server file that implements it.

Can I grant, cancel or refund subscriptions through the API?

You can grant promotional access for any store. Cancel, refund and defer work for Google Play subscriptions. For App Store subscriptions, RevenueDot can extend a renewal, but Apple does not let a server cancel or refund.

Are there endpoints that RevenueCat does not have?

Yes, and they are marked as RevenueDot extensions. They include funnels, purchase links, web products, Refund Control, retention offers, support summaries, data exports, ads and reward rules, and the importer's endpoints.

Get started

Run subscriptions without the revenue share.

Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.

Already have an account? Sign in · Prefer your own servers? Self-host free